Skip to content

Glossary · Compliance

Subprocessor

A subprocessor is a third party that a processor engages to carry out part of the processing of personal data on the controller’s behalf — a hosting provider, a payment provider or an email relay, for example.

Open betaThe platform is being built in the open, so parts of it are not there yet, behaviour changes between releases, and no availability figure is committed while it is in beta. What is still being built.

Also called

Sub-processor

What Subprocessor means

The chain matters because the controller’s obligations do not stop at the first vendor. Article 28 requires the processor to impose the same data protection terms on anybody it engages, and to remain fully liable to the controller for what that party does. A vendor cannot subcontract away a duty it owes.

Two forms of authorisation exist. Specific authorisation means the controller approves each subprocessor individually, which is thorough and unworkable at scale. General authorisation means the controller approves the practice in advance on condition of being notified of changes and given a right to object, which is what nearly every SaaS contract uses. The value of general authorisation depends entirely on the notice period actually being honoured.

The most common defect in a subprocessor disclosure is not an omission but a divergence: the list in the privacy notice and the list in the DPA annex have drifted apart. A reviewer who checks both and finds different names has learned something about the vendor’s process, not just about its subprocessors.

How Enclessa uses it

Enclessa maintains a subprocessor list covering hosting, payments, transactional email and operational tooling, and commits to keeping the DPA annex and the privacy notice in step with each other. The specific entities and the notice period are recorded on the trust centre; where a value is not yet settled in the repository it appears as a marked placeholder rather than a guess.

Where Subprocessor is specified

Related terms

Read further

The security page explains how Enclessa protects data and which certifications it does not hold. The trust centre covers the processing agreement, the subprocessors and the residency position. The FAQ answers the questions buyers ask most often.

Encrypted collaboration, hosted in Europe.

Create a workspace in a couple of minutes. It is yours at your-team.enclessa.app, hosted in the European Union, with encrypted direct messages from the first one you send.

Open beta. Free plan, no payment card to start.